SIEM Security Engineer
EY
EY
Join EY as a SIEM Security Engineer in our Global Delivery Services (GDS) center in India, playing a crucial role in the Security Technology Services (STS) group. This hands-on engineering position focuses on the deployment, configuration, integration, and maintenance of our Microsoft Sentinel SIEM platform and related security monitoring tools across diverse environments. You'll have the opportunity to enhance your technical skills while contributing significantly to enterprise-scale threat detection and response, collaborating with a global team.
This role offers a unique chance to build a career within EY's inclusive culture, leveraging global scale and technology to foster personal and professional growth. We value unique perspectives and are committed to building a better working world for everyone.
As a SIEM Engineer, you will: - Oversee the deployment, configuration, and management of SIEM solutions, adhering to EY standards across on-premises, hybrid, and cloud infrastructures. - Support the implementation and management of Azure Monitor Agent (AMA) and Azure ARC. - Manage data pipeline operations, including onboarding new log sources and utilizing Syslog/CEF ingestion. - Assist in developing automated response workflows using Logic Apps and Azure Functions. - Contribute to data transformation efforts, including log normalization, parsing, and ingestion volume optimization. - Support external cloud log ingestion pipelines from vendors like AWS and GCP. - Act as a technical escalation point for SOC analysts regarding SIEM queries. - Create and maintain essential technical documentation, such as runbooks and configuration guides.
To excel in this role, you should possess: - 3-5 years of experience in IT Security or a related technical domain, with a strong focus on SIEM engineering. - Practical experience with Microsoft Sentinel or a comparable SIEM platform. - Basic proficiency in KQL or similar query languages for log analysis and rule development. - Foundational knowledge of cloud environments, particularly Azure, with exposure to AWS or GCP. - Basic scripting skills in Python, PowerShell, or Bash for automation tasks. - Understanding of common security event sources like Windows Event Logs, Syslog, firewalls, and endpoint agents. - A bachelor’s degree in Computer Science, Engineering, IT, Mathematics, or equivalent practical experience is preferred.
EY Global Delivery Services ( EY GDS)
IT Consulting